mirror of
https://github.com/Terncode/pixel.horse.git
synced 2026-09-24 13:55:04 +02:00
Security: Don't allow default secret/token config parameters (#80)
This commit is contained in:
@@ -181,6 +181,16 @@ Add `config.json` file in root directory with following content. You can use `co
|
|||||||
}
|
}
|
||||||
```
|
```
|
||||||
|
|
||||||
|
### NOTE!
|
||||||
|
|
||||||
|
You **MUST** provide **unique**, **random** values for the `secret` and `token` fields of your config. It is **extremely dangerous** to leave these as default, as these values serve as authentication tokens for internal APIs and session cookies.
|
||||||
|
|
||||||
|
To generate new values for these parameters, you can use the following command:
|
||||||
|
|
||||||
|
```bash
|
||||||
|
node -e "console.log(require('crypto').randomBytes(64).toString('base64'))"
|
||||||
|
```
|
||||||
|
|
||||||
## Running
|
## Running
|
||||||
|
|
||||||
### Your first build
|
### Your first build
|
||||||
|
|||||||
@@ -7,8 +7,8 @@
|
|||||||
"host": "http://localhost:8090/",
|
"host": "http://localhost:8090/",
|
||||||
"local": "localhost:8090",
|
"local": "localhost:8090",
|
||||||
"adminLocal": "localhost:8091",
|
"adminLocal": "localhost:8091",
|
||||||
"secret": "gfhfdshtrdhgedryhe4t3y5uwjthr",
|
"secret": "<some_random_string_here>",
|
||||||
"token": "sdlfgihsdor8ghor8dgdrgdegrdg",
|
"token": "<some_random_string_here>",
|
||||||
"db": "mongodb://<username>:<password>@localhost:27017/<database_name>",
|
"db": "mongodb://<username>:<password>@localhost:27017/<database_name>",
|
||||||
"oauth": {
|
"oauth": {
|
||||||
"google": {
|
"google": {
|
||||||
|
|||||||
@@ -57,6 +57,36 @@ export const args = argv as AppArgs;
|
|||||||
export const { version, description }: AppPackage = require('../../../package.json');
|
export const { version, description }: AppPackage = require('../../../package.json');
|
||||||
export const config: AppConfig = require('../../../config.json');
|
export const config: AppConfig = require('../../../config.json');
|
||||||
|
|
||||||
|
if (!DEVELOPMENT && !TESTS &&
|
||||||
|
(!config.secret || !config.token
|
||||||
|
|| config.secret.length < 16
|
||||||
|
|| config.token.length < 16
|
||||||
|
|| config.secret === config.token
|
||||||
|
|| config.secret === 'gfhfdshtrdhgedryhe4t3y5uwjthr'
|
||||||
|
|| config.token === 'sdlfgihsdor8ghor8dgdrgdegrdg'
|
||||||
|
|| config.secret === '<some_random_string_here>'
|
||||||
|
|| config.token === '<some_random_string_here>')) {
|
||||||
|
console.error(
|
||||||
|
`
|
||||||
|
================================================================================
|
||||||
|
WARNING! WARNING! WARNING!
|
||||||
|
|
||||||
|
Your config parameters token and secret appear to be insecure!
|
||||||
|
This is **VERY** insecure, as these values serve as authentication tokens for
|
||||||
|
internal APIs and session cookies. You **must** change these values in order to
|
||||||
|
prevent potential exploits.
|
||||||
|
|
||||||
|
To generate new values for these parameters, you can use the following command:
|
||||||
|
node -e "console.log(require('crypto').randomBytes(64).toString('base64'))"
|
||||||
|
|
||||||
|
Exiting here, as the security of your application cannot be guaranteed...
|
||||||
|
================================================================================
|
||||||
|
`
|
||||||
|
);
|
||||||
|
|
||||||
|
process.exit(1);
|
||||||
|
}
|
||||||
|
|
||||||
const loginServer: ServerConfig = { id: 'login', filter: false, port: config.port } as any;
|
const loginServer: ServerConfig = { id: 'login', filter: false, port: config.port } as any;
|
||||||
const adminServer: ServerConfig = { id: 'admin', filter: false, port: config.adminPort || config.port } as any;
|
const adminServer: ServerConfig = { id: 'admin', filter: false, port: config.adminPort || config.port } as any;
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user